The Socomec DIRIS Digiware M-70 is an industrial gateway for power monitoring, used in critical infrastructure sectors such as data centers, manufacturing plants, and industrial facilities. These devices provide essential visibility into electrical power consumption and quality, making them fundamental for operational stability and safety. The business criticality associated with these devices is high: a malfunction can prevent operators from detecting potentially harmful power fluctuations or outages.
This vulnerability poses a significant risk because it allows a fully unauthenticated attacker on the network to render the device unusable remotely, causing a denial-of-service (DoS) condition. The attack is of low complexity and requires only specially formatted network packets, with a publicly available proof-of-concept, making abuse highly likely.
Any organization with these devices connected to untrusted networks, including the Internet, is at immediate risk. The consequences of exploitation include the loss of monitoring capabilities, which can lead to operational downtime, breaches of Service Level Agreements (SLAs), and potential equipment damage due to undetected power issues. This is a critical risk for Operational Technology (OT) that requires immediate attention.
| Product | Socomec DIRIS Digiware M-70 |
| Date | 2025-12-05 00:19:58 |
Technical Summary
The vulnerability exists in the Modbus TCP service running on TCP port 502 of the Socomec DIRIS Digiware M-70 device. The root cause is an access control error during the handling of specific Modbus commands, which allows an unauthenticated user to modify a critical system configuration parameter.
The attack chain is as follows:
- An attacker establishes a connection to the Modbus listener on TCP port 502. No authentication is required.
- The attacker sends a specific sequence of three ‘Write Single Register’ (function code 6) messages.
- These messages are directed at the register that controls the Modbus address of the device itself. The device firmware does not verify that this sensitive configuration change comes from an authorized source.
- After accepting the change, the device enters an unstable state, stops responding to any network communication, and halts its monitoring functions. A manual power cycle is required to restore operation.
An unauthenticated remote attacker can exploit this vulnerability to cause a persistent denial-of-service state, effectively disabling the energy monitoring capabilities of the target infrastructure.
Affected versions:
- Socomec DIRIS Digiware M-70, firmware version 1.6.9 and possibly earlier versions.
A patched firmware version was not specified in the initial advisory. Users should consult the vendor to obtain the latest security updates.
Recommendations
- Apply patches immediately: Consult Socomec’s manufacturer security advisories for the latest patch information and update as soon as a corrected firmware version is made available.
- Mitigations:
- Critical: Restrict network access to the Modbus service on TCP port 502. Access should only be permitted to trusted hosts within dedicated OT or management networks.
- Verify that the device is not exposed to the Internet. Use firewalls or Access Control Lists (ACLs) to block all inbound traffic on port 502 from external networks.
- Implement proper network segmentation to isolate Industrial Control Systems (ICS) and OT networks from corporate IT networks.
- Monitoring and Threat Hunting:
- Monitor firewall and network logs for connection attempts to TCP port 502 from untrusted or unexpected IP addresses.
- Analyze network traffic for unusual patterns of Modbus function code 6 (‘Write Single Register’) commands, particularly multiple sequential requests from a single source directed at the affected devices.
- Configure alerts to detect when a DIRIS Digiware M-70 device goes offline unexpectedly or stops responding to polling.
- Incident Response:
- In the event of a device malfunction, isolate it from the network immediately to prevent further interaction by the attacker.
- Perform a manual power cycle to restore its operational state.
- Retain network logs and analyze them to identify the source IP address that sent the malicious Modbus packets. Implement blocking rules for the identified source.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
